<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_pepperlfuchsse</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:59:27 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-014 — Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-014</link>
      <description>&lt;p&gt;The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-014</guid>
      <pubDate>Wed, 16 Sep 2026 08:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-017 — Pepperl+Fuchs: ICE2- * and ICE3- * are affected by multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-017</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Denial of service
Bypassing of authentication
Information disclosure&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the product due to outdated software components.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Denial of service
Bypassing of authentication
Information disclosure&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-017</guid>
      <pubDate>Wed, 10 Apr 2024 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-011 — PEPPERL+FUCHS: Profinet Gateway LB8122A.1.EL – Device is affected by XSS vulnerability and information disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-011</link>
      <description>&lt;p&gt;A stored cross-site scripting vulnerability has been discovered in the profinet gateway LB8122A.1.EL. An attacker can write an HTML tag with up to 32 characters in the message field of a HART transmitter. The HTML tag is interpreted as HTML when the HART information is displayed in a webbrowser. If the HTML tag contains a link to a manipulated page, a user can be tricked into accessing this page.
Furthermore, an attacker can access information about running processes via the SNMP protocol. Sending such SNMP read commands can also trigger a reboot.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored cross-site scripting vulnerability has been discovered in the profinet gateway LB8122A.1.EL. An attacker can write an HTML tag with up to 32 characters in the message field of a HART transmitter. The HTML tag is interpreted as HTML when the HART information is displayed in a webbrowser. If the HTML tag contains a link to a manipulated page, a user can be tricked into accessing this page.
Furthermore, an attacker can access information about running processes via the SNMP protocol. Sending such SNMP read commands can also trigger a reboot.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-011</guid>
      <pubDate>Mon, 26 May 2025 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-038 — Pepperl+Fuchs: Anonymous FTP server and Telnet access allows information disclosure and manipulation</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-038</link>
      <description>&lt;p&gt;Critical vulnerabilities has been discovered in the product, mainly caused by ananonymous FTP server and Telnet access.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Information disclosure
Denial of service
Device manipulation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities has been discovered in the product, mainly caused by ananonymous FTP server and Telnet access.The impact of the vulnerabilities on the affected device may result in&lt;/p&gt;
&lt;p&gt;Information disclosure
Denial of service
Device manipulation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-038</guid>
      <pubDate>Wed, 10 Jul 2024 06:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-002 — PEPPERL+FUCHS: HMI – devices are affected by Windows RCE</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-002</link>
      <description>&lt;p&gt;An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An unauthenticated attacker could repeatedly send IPv6 packets, that include specially crafted packets, to a Windows machine which could enable remote code execution.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-002</guid>
      <pubDate>Tue, 25 Feb 2025 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2022-021 — Pepperl+Fuchs: RSM-EX devices - Multiple Bluetooth vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2022-021</link>
      <description>&lt;p&gt;Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner&amp;#39;s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue. Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN. Bluetooth LE and BR/EDR secure pairing in Bluet…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (participating in the provisioning protocol) to identify the AuthValue used given the Provisioner&amp;#39;s public key, and the confirmation number and nonce provided by the provisioning device. This could permit a device without the AuthValue to complete provisioning without brute-forcing the AuthValue. Bluetooth Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, reflecting the authentication evidence from a Provisioner, to complete authentication without possessing the AuthValue, and potentially acquire a NetKey and AppKey. Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without possession of the AuthValue used in the provisioning protocol) to determine the AuthValue via a brute-force attack (unless the AuthValue is sufficiently random and changed each time). Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to conduct a successful brute-force attack on an insufficiently random AuthValue before the provisioning procedure times out, to complete authentication by leveraging Malleable Commitment. Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN. Bluetooth LE and BR/EDR secure pairing in Bluet…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2022-021</guid>
      <pubDate>Mon, 16 May 2022 14:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2021-041 — Pepperl+Fuchs: Multiple DTM and VisuNet Software affected by log4net vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2021-041</link>
      <description>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.&lt;/p&gt;
&lt;p&gt;UPDATE A: Remediation: added fixed VisuNet Products&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Critical vulnerabilities have been discovered in the utilized component log4net by Apache Software Foundation.&lt;/p&gt;
&lt;p&gt;UPDATE A: Remediation: added fixed VisuNet Products&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2021-041</guid>
      <pubDate>Tue, 26 Oct 2021 13:35:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-053 — Pepperl+Fuchs: Comtrol RocketLinx ICRL-M - Multiple Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-053</link>
      <description>&lt;p&gt;Several critical vulnerabilities within firmware.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several critical vulnerabilities within firmware.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-053</guid>
      <pubDate>Mon, 08 Mar 2021 13:44:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2020-017 — Pepperl+Fuchs, PACTware: Two password vulnerabilities found</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-017</link>
      <description>&lt;p&gt;PACTware passwords are stored in a recoverable format (CVE-2020-9403)&lt;/p&gt;
&lt;p&gt;PACTware passwords may be modified without knowing the current password (CVE-2020-9404)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PACTware passwords are stored in a recoverable format (CVE-2020-9403)&lt;/p&gt;
&lt;p&gt;PACTware passwords may be modified without knowing the current password (CVE-2020-9404)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-017</guid>
      <pubDate>Fri, 29 May 2020 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2024-033 — PEPPERL+FUCHS: Device Master ICDM-RX/* – Vulnerability may allow unauthenticated remote attacker information disclosure…</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-033</link>
      <description>&lt;p&gt;Vulnerabilities have been discovered in the product, mainly caused by HTML injection and crosssite-scripting.  
The impact of the vulnerability on the affected device may result in an information disclosure and denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerabilities have been discovered in the product, mainly caused by HTML injection and crosssite-scripting.  
The impact of the vulnerability on the affected device may result in an information disclosure and denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-033</guid>
      <pubDate>Tue, 13 Aug 2024 12:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
